Cloudflare edge and response protection
Cloudflare delivers the site with HTTPS and edge protection, while restrictive content, framing, referrer, capability, and cross-origin policies reduce browser-side exposure.
Security
Eigenexis Systems protects this public website with Cloudflare edge controls, restrictive response policies, server-side validation, and private application storage reserved for a separately gated early-access workflow. These website controls remain distinct from the unreleased desktop product, whose security and update model must pass its own qualification before public beta.
Context
The production site uses HTTPS, DNSSEC, restrictive content and framing policies, same-origin boundaries, and security headers across pages, assets, redirects, API responses, and errors.
Potential early-access submissions are bounded and validated on the server. Replay and abuse controls, scheduled retention cleanup, structured operational events, and rollback procedures have been qualified, while real applicant intake remains disabled.
No system can be guaranteed impossible to compromise. These safeguards reduce defined risks and require continuing verification as the service changes.
Workflow
The intake endpoint accepts only approved same-origin JSON requests with the expected method, fields, consent version, and bounded values. Unexpected or malformed submissions receive generic responses.
Accepted records use private server-side application storage. The browser receives no database credentials or record-reading authority, and the application record excludes payment information, browser fingerprints, forwarding headers, and IP addresses.
Expired application data and short-lived abuse-control state are removed by a deployed schedule. Structured security events and tested recovery procedures support operational review without logging applicant fields or secrets.
Scope
Cloudflare delivers the site with HTTPS and edge protection, while restrictive content, framing, referrer, capability, and cross-origin policies reduce browser-side exposure.
Same-origin controls, bounded inputs, schema validation, consent, replay resistance, abuse controls, private storage, and generic errors protect the request path.
Structured events, scheduled cleanup, dependency checks, deployment verification, and tested rollback procedures support maintenance and recovery without claiming continuous human monitoring.
No system can be guaranteed impossible to compromise. Controls reduce defined risks, require maintenance, and must be revalidated when infrastructure or product behaviour changes.
A monitored security mailbox is not yet operational, so the disclosure policy remains an interim reporting boundary and real applicant intake remains disabled. These website safeguards are not evidence of future desktop-product security.
Questions
No. Implemented controls reduce defined risks, but security requires continuing maintenance, monitoring, testing, and accurate disclosure of residual risk.
The application record does not store IP addresses, browser user-agent strings, client-hint fingerprints, forwarded network identifiers, or payment information. Cloudflare may process limited connection and security data to deliver and protect the service under its own service practices.
Read the vulnerability-disclosure page and follow its current reporting boundary. A monitored private mailbox is still being commissioned, so do not transmit non-public vulnerability details until that page and security.txt publish a verified reporting address.
Tell Eigenexis Systems what you need to edit, draw, measure, search, complete, or review before the planned Windows public beta.
Request early access